|
199541
|
5.5 |
MEDIUM
Local
|
tcmu-runner_project
|
tcmu-runner
|
The tcmu-runner daemon in tcmu-runner version 1.0.5 to 1.2.0 is vulnerable to a local denial of service attack
|
CWE-20
Improper Input Validation
|
CVE-2017-1000201
|
2024-11-21 12:04 |
2017-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199542
|
7.5 |
HIGH
Network
|
tcmu-runner_project
|
tcmu-runner
|
tcmu-runner version 1.0.5 to 1.2.0 is vulnerable to a dbus triggered NULL pointer dereference in the tcmu-runner daemon's on_unregister_handler() function resulting in denial of service
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-1000200
|
2024-11-21 12:04 |
2017-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199543
|
7.5 |
HIGH
Network
|
tcmu-runner_project
|
tcmu-runner
|
tcmu-runner version 0.91 up to 1.20 is vulnerable to information disclosure in handler_qcow.so resulting in non-privileged users being able to check for existence of any file with root privileges.
|
CWE-200
Information Exposure
|
CVE-2017-1000199
|
2024-11-21 12:04 |
2017-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199544
|
7.5 |
HIGH
Network
|
tcmu-runner_project
|
tcmu-runner
|
tcmu-runner daemon version 0.9.0 to 1.2.0 is vulnerable to invalid memory references in the handler_glfs.so handler resulting in denial of service
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-1000198
|
2024-11-21 12:04 |
2017-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199545
|
9.8 |
CRITICAL
Network
|
octobercms
|
october
|
October CMS build 412 is vulnerable to file path modification in asset move functionality resulting in creating creating malicious files on the server.
|
CWE-417
Channel and Path Errors
|
CVE-2017-1000197
|
2024-11-21 12:04 |
2017-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199546
|
9.8 |
CRITICAL
Network
|
octobercms
|
october
|
October CMS build 412 is vulnerable to PHP code execution in the asset manager functionality resulting in site compromise and possibly other applications on the server.
|
CWE-94
Code Injection
|
CVE-2017-1000196
|
2024-11-21 12:04 |
2017-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199547
|
7.5 |
HIGH
Network
|
octobercms
|
october
|
October CMS build 412 is vulnerable to PHP object injection in asset move functionality resulting in ability to delete files limited by file permissions on the server.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2017-1000195
|
2024-11-21 12:04 |
2017-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199548
|
9.8 |
CRITICAL
Network
|
octobercms
|
october
|
October CMS build 412 is vulnerable to Apache configuration modification via file upload functionality resulting in site compromise and possibly other applications on the server.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2017-1000194
|
2024-11-21 12:04 |
2017-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199549
|
6.1 |
MEDIUM
Network
|
octobercms
|
october
|
October CMS build 412 is vulnerable to stored WCI (a.k.a XSS) in brand logo image name resulting in JavaScript code execution in the victim's browser.
|
CWE-79
Cross-site Scripting
|
CVE-2017-1000193
|
2024-11-21 12:04 |
2017-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199550
|
9.8 |
CRITICAL
Network
|
pidusage_project
|
pidusage
|
soyuka/pidusage <=1.1.4 is vulnerable to command injection in the module resulting in arbitrary command execution
|
CWE-78
OS Command
|
CVE-2017-1000220
|
2024-11-21 12:04 |
2017-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|